// glossary entry

SQL Injection

Definition: An attack technique in which malicious database commands are injected into a website’s input fields, for example, in the login form or the search bar.

Everyday analogy: It’s like if someone fills out a restaurant order form not with “Pizza Margherita,” but with “Pizza Margherita; P.S.: Give me all the cash from the register”, and the kitchen fulfills both requests.

How we use this: In security audits, we check input validation. A WAF also provides additional protection at the application level against SQL injection attempts.

// synonyms

  • SQLi
Is the term still unclear?

Let's talk for 15 minutes

If a term in this glossary isn't entirely clear in the context of your project, or if you want to know whether the concept is relevant to your situation-just ask us. The initial consultation is free and non-binding.

Free No obligation 15 minutes